Google and OpenDNS made the web faster for everyone today
extremetech.com
extremetech.com
If you run your own DNS server, then the browser DNS prefetch is already allowing you to be tracked, and by full IP address rather than just the first three octets. On the other hand, most people do not run their own DNS server, so GIS is a reduction of privacy.
Is it this?
"Basically, when your browser makes a DNS request, the DNS server will now forward the first three octets (123.45.67) of your IP address to the target web service."
So say you search for something on google; google returns its search results page, your browser gets the page, looks at all the links, asks DNS for the IP's to all those links' addresses, and DNS auto-sends YOUR (truncated) IP to all those addresses' servers?
I guess I'm unclear on why it would do that. If the truncated IP coming to a CDN isn't coming with an actual request, how do they know that at some time later your actual request is from your truncated IP? (I also don't understand why a CDN would use some sort of DNS address as a geolocation strategy, but I guess that's another discussion.)
Yes.
> I guess I'm unclear on why it would do that.
The DNS prefetching done by the browser exists to save your time. Instead of waiting to do a DNS lookup until you click on a link in the current page, the browser does DNS lookups on all links in the page as soon as the page is loaded. By the time you're done deciding which link to follow, the browser is already done with the initial step required to follow any link on the page.
> If the truncated IP coming to a CDN isn't coming with an actual request, how do they know that at some time later your actual request is from your truncated IP? (I also don't understand why a CDN would use some sort of DNS address as a geolocation strategy, but I guess that's another discussion.)
You seem to have misread the description.
A CDN is a group of multiple servers and all of them could, in theory, respond to your request for a specific web page. The servers in the group are spread out all over the globe, but all of them share the same domain name. When you look up the IP address of the shared domain name, this new GIS draft sends your truncated IP address to the DNS server of the CDN so it can choose the server in the group that is "closest" to you.
I hope that makes more sense.
My apologies; I was unclear. I (think I) get the DNS prefetching idea (your browser asks DNS for all the IP's on a page in the hope that one will be hit, and it won't have to spend time to do it later when a link is actually clicked), but why would DNS send anything to the site that it's getting an address for? (And under what protocol?)
When my browser asks DNS for an IP for "www.foo.com", why does "www.foo.com" need to know I asked for it?
The approaching exhaustion of IPv4 in the coming years, and how, in practice, it is handled could make a real mess of GIS. If your ISP starts handing out IPv4 addresses in the private address space to customers and does transparent PNAT, then GIS breaks badly for all customers of said ISP. In the case of large ISPs, GIS could actually make things slower.
The part I have no clue about is how GIS works with IPv6? I haven't read the IETF draft, so I'll just shut up and hope someone more knowledgeable chimes in here.
How is that? ARIN doesn't delegate IP address space to users or ISPs in smaller segments than 1024K IP addresses. So it seems that 3 octets is enough to map to a physical location. How does the additional octet give you additional geolocational abilities?
RequestPolicy users can disable Link prefetching and DNS prefetching from the Advanced tab in the RequestPolicy preferences. Everyone else can search for "prefetch" in about:config and do it from there.
Also, Prefetching is disabled by default if the page containing the link is opened over HTTPS.
If you've ever seen the painfully common DNS issues on Verizon Wireless, you'd know why I'm asking. ;)
Authoritative nameservers handling http requests? Mine certainly don't.
Or did you mean to say that you only send edns-option to the server that is authoritative for the domain being requested?
Fixing that has tremendous benefits.
That's the real issue - previously these DNS servers did not work well with CDNs because they didn't send the location of the client making the request to the origin server. This extension fixes that problem.
If you aren't using these DNS servers then CDNs probably route your requests properly.
I live in Australia at the end of a very long trans-pac pipe, and properly configured CDNs make a huge difference. A great example is how a few cheap ISPs here route based on price, not latency. That meant that when Amazon opened their Singapore dataceter a visitor from Australia (using one of these ISPs) could be routed via the US West Coast.
Title isn't misleading, but your comment is.
(Akamai is my main reason of not using OpenDNS to this date, otherwise I would make a switch for long)
But yeah, some big guys still remain! We'll get 'em.
This is a workaround for a specific problem with public DNS servers, and while it's not a bad one, we shouldn't pretend it's going to help everyone.
Or do you mean that ISP DNS servers are generally close geographically?
I guess we'll need the input of someone who works at an ISP :)
The UK has a small land area, and so latency talking to the other side of the continent is nowhere near as much an issue.
I think this does give a bit more power to the geo-aware dns services (such as Cisco GSS), if they implement it.. but it's a long way off, as many ISPs and networks would need to upgrade their resolvers to support this extension.
http://tools.ietf.org/html/draft-vandergaast-edns-client-sub...
Caching works just fine. There is some cache inefficiency, but memory is cheap. Really cheap. http://www.jcmit.com/mem2010.htm
You can't even change this without mucking around in the internal read-only filesystem. You can certainly assign new DNS nameservers after you've DHCP'd, but in that case, why not pick faster DNS servers than Google's?
divine???
Even more - when I Google for "divine v. [trans.]: to discover or locate" -- the only link is to your comment on hackerstream.
I see that definition at http://www.merriam-webster.com/dictionary/divine?show=2
(To not have the creators of hackerstream come crawling out of the woodwork, you may refer to it as 'that which shall not be named'.)